Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

fix(nodejs-express-server): remove unused axios dependency #20707

Merged
merged 1 commit into from
Feb 22, 2025

Conversation

gus-costa
Copy link
Contributor

Remove axios from package.mustache as it's not used in the starter build. This eliminates potential security vulnerabilities (ReDos & SSRF) from the dependency tree without affecting functionality.

fix #10427

PR checklist

  • Read the contribution guidelines.
  • Pull Request title clearly describes the work in the pull request and Pull Request description provides details about how to validate the work. Missing information here may result in delayed response from the community.
  • Run the following to build the project and update samples:
    ./mvnw clean package || exit
    ./bin/generate-samples.sh ./bin/configs/*.yaml || exit
    ./bin/utils/export_docs_generators.sh || exit
    
    (For Windows users, please run the script in Git BASH)
    Commit all changed files.
    This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
    These must match the expectations made by your contribution.
    You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example ./bin/generate-samples.sh bin/configs/java*.
    IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.
  • File the PR against the correct branch: master (upcoming 7.x.0 minor release - breaking changes with fallbacks), 8.0.x (breaking changes without fallbacks)
  • If your PR is targeting a particular programming language, @mention the technical committee members, so they are more likely to review the pull request. @CodeNinjai (2017/07) @frol (2017/07) @cliffano (2017/07)

Remove axios from package.mustache as it's not used in the starter build.
This eliminates potential security vulnerabilities (ReDos & SSRF) from
the dependency tree without affecting functionality.
@wing328 wing328 added this to the 7.12.0 milestone Feb 22, 2025
@wing328 wing328 merged commit f83b049 into OpenAPITools:master Feb 22, 2025
15 checks passed
@wing328
Copy link
Member

wing328 commented Feb 22, 2025

thanks for the PR

i pushed cea3c5b to update the samples

@gus-costa gus-costa deleted the nodejs-axios branch February 24, 2025 12:14
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[REQ] [nodejs.express.server] Remove unused axios package from package.mustache
2 participants